If you are using a client (RDM, PowerShell, etc.), version 2026.3 is required for this DVLS version
NEW FEATURES
- Core - Added a new encryption format for RDM export files
- Core - Added a one-time self-service extension for expired trials
- Core - Added custom user tags for filtering, sorting, reporting, and conditional access
- Core - Added granular administrative roles for more precise permission management
- Core - Added individual forbidden password rules with configurable matching modes
- Core - Added PostgreSQL support as a Devolutions Server database backend
- PAM - Added an option to keep Microsoft 365 and Active Directory JIT accounts between checkouts
- PAM - Added self-rotation for PAM provider credentials
- PAM - Added the ability to extend active PAM checkouts without checking in and requesting access again
- PAM - Merged PAM and shared vaults, allowing PAM credentials to be stored in regular high-security vaults
- Web - Added a compact kiosk view displaying web-launchable sessions as tiles
IMPROVEMENTS
- Core - Added a setting to configure how long log files are retained on disk
- Core - Added checkout support for folders and multiple selections
- Core - Added expiration dates for user accounts
- Core - Added missing Remote Desktop Manager variables so scripts and entries now resolve them correctly
- Core - Added paging for large Active Directory group lists used by automatic user creation filters
- Core - Added SSH key support to Bitwarden synchronization
- Core - Added the ability to check out linked entries directly from the overview
- Core - Hidden the "Submit a support ticket" action when internet features are disabled
- Core - Imports now warn about entries with forbidden or policy-violating passwords instead of blocking them
- Core - Improved performance when moving entries to vaults containing thousands of entries
- Core - Improved support for vault templates when saving system settings
- Core - Linked credentials are now automatically checked out when used
- Core - Prevented connection logs linked to session recordings from being archived or purged
- Core - Removed unusable PSU licenses from the interface
- Core - Trimmed leading and trailing spaces from usernames during emergency login
- PAM - Added a dedicated permission for manually creating PAM accounts
- PAM - Added an option to skip TLS validation for the Windows provider
- PAM - Added AnyIdentity provider support through Devolutions Gateway and on Linux using cross-platform PowerShell remoting
- PAM - Added on-demand account discovery directly from the PAM providers list
- PAM - Added visibility of inherited checkout policy values
- Web - Added a session recording log viewer with an activity timeline
- Web - Added support for DVLS Privileged Account credentials
- Web - Added the "Allow password in variable" security setting to username and password credentials
- Web - Added the ability to delete multiple attachments at once
- Web - Added the ability to download multi-part session recordings as a single ZIP file
- Web - Added the ability to run saved Scripts/Macros entries in web PowerShell and SSH terminals
- Web - Added the ability to run scripts in PowerShell sessions opened through Devolutions Gateway
- Web - Converted legacy Website entries to the current entry type
- Web - Improved AI Assistant answer and approval prompt positioning
- Web - Improved the search and advanced search experience
- Web - Refreshed the user menu side panel layout
- Web - Restored ticketing administration for Jira, ServiceNow, and HaloPSA
FIXES
- Core - Fixed a SQL timeout when renaming folders containing more than 3,500 entries
- Core - Fixed administrators being unable to reset a contractor's password
- Core - Fixed an issue where moving entries between vaults failed and could break linked credentials
- Core - Fixed an issue where moving entries to another vault no longer worked
- Core - Fixed an issue where the "Force MFA" setting could remain enabled after migrating from SQL to DVLS with no way to disable it
- Core - Fixed an issue where the server could remain permanently in maintenance mode after an interrupted maintenance run
- Core - Fixed automatic database retention cleanup not running when using a non-English SQL login
- Core - Fixed contractors being able to change or remove their own 2FA configuration without re-entering their password
- Core - Fixed database upgrades timing out during long-running steps, particularly on Azure SQL
- Core - Fixed notification preference emails containing a mix of translated and English text
- Core - Fixed partially translated email notifications and improved their date formatting
- Core - Fixed renamed folders and their contents disappearing from the connection tree
- Core - Fixed scheduled database retention incorrectly archiving or purging records within the configured retention period
- Core - Fixed support ticket submissions reporting success without creating a support case
- Core - Fixed the offline synchronization document size limit exceeding the value supported by Remote Desktop Manager
- Core - Fixed the scheduler service crashing when a custom log retention policy contained invalid values
- Core - Fixed the User column appearing blank in Global Open Sessions when Remote Desktop Manager was connected to a Devolutions Server data source
- Core - Fixed ticket prompts accepting free-form text when an existing ticket was required
- Core - Fixed user vault entry errors after migrating a SQL data source to DVLS
- Core - Fixed vault and folder password complexity policies being displayed as inherited without being enforced
- Core - Harmonized checkout and check-in behavior across platforms
- Gateway - Fixed an error when trusting a Devolutions Gateway certificate on Kestrel-hosted instances
- Gateway - Fixed incorrect gateway host and port resolution for native iLO and SQL Server sessions
- Gateway - Fixed session recording failures for Active Directory Console entries using a Devolutions Gateway farm
- Gateway - Fixed session recordings being larger than expected because configured frame rate and resolution settings were ignored
- PAM - Fixed accounts incorrectly appearing as Out of sync in Remote Desktop Manager
- PAM - Fixed Active Directory discovery, OU browsing, and group lookups failing with trusted domain controller certificates
- PAM - Fixed Active Directory TLS certificate validation and trusted certificate issues affecting discovery, OU browsing, and group retrieval
- PAM - Fixed an error when filtering containers during account discovery
- PAM - Fixed an issue where Active Directory account discovery returned no accounts for child domains when the forest root was unreachable
- PAM - Fixed an issue where moving a PAM entry to a folder in another vault failed
- PAM - Fixed checkouts not expiring and scheduled password rotations not running when many accounts were checked out simultaneously
- PAM - Fixed Cisco and MySQL password reset providers being uneditable after creation and restored the Cisco username field
- PAM - Fixed PAM account lifecycle and checkout policies being creatable without a valid PAM license
- PAM - Fixed PAM accounts incorrectly appearing as "Out of sync" in Remote Desktop Manager
- PAM - Fixed the "Automatically check in PAM account" setting displaying the wrong value
- PAM - Fixed the total checkout time being displayed incorrectly when an account was automatically checked in
- PAM - Fixed the View and Copy one-time password actions being unavailable in Remote Desktop Manager for checked-out PAM accounts with OTP configured
- PAM - Fixed users with a PAM provider role losing access to the Privileged Access section
- Web - Fixed closing a session from the kebab menu redirecting to Administration > Vaults instead of the current vault, and corrected the disconnect message
- Web - Fixed entries disappearing from the Connections tree when moved by drag and drop while a filter was active
- Web - Fixed long entry names being truncated in the Sessions tree and hiding the session recording indicator
- Web - Fixed Telnet sessions terminating unexpectedly
- Web - Fixed terminal sessions leaving network connections open after being ended from the server side
- Web - Fixed the "Find by name (user vault)" dialog displaying irrelevant results when no entry matched
- Web - Fixed the Connections tree not refreshing after deleting an entry while a filter was active
- Web - Fixed the Credentials dropdown offering "Linked (cross vault)" for user vault entries when the option was disabled
- Web - Multiple UI fixes
- Web - Multiple UI fixes
** CONSOLE RELEASE NOTES **
IMPROVEMENTS
- Added a `--disable-telemetry` option to the IIS command-line installer to disable telemetry during installation
FIXES
- Fixed a "Could not apply least permissions" error when updating a server instance
- Fixed an error when editing and saving a Kestrel instance in maintenance mode
- Fixed an upgrade removing the scheduler account's permissions on the encryption configuration file
- Fixed duplicate Light and Dark theme options under Support > Options > Theme
- Fixed server instance changes made from the Console not being saved
- Fixed the command-line interface crashing when upgrading a server instance
- Fixed upgrades removing the scheduler account's permission to access the encryption configuration file